[Warning] Malicious file about portrait infringement
INCA Internet response team detected malicious file which contains malicious file disguised as a portrait file from 04 May 2012. On April, various reports about this file can be found on internet so far, yet it can be found in Korea. Besides, this malicious file has various variants; we add patterns on our nProtect Anti-Virus. Containing EXE(ZIP)file on attachment of e-mail has great possibility to be revealed as a malicious file.
2. Real cases
IMG0893.zip - Your photo all over Facebook? Naked? Malware campaign spammed out
[nProtect Response Team Official Blog]
[Caution] Malicious e-mail about BBB(Better Business Bureau)
Following image contains various malicious files. The title of e-mail is "FW:Why did you put this photo online?" (It may contain about portrait infringement)
To Korea May 4, 2012
To Germany May 8, 2012
To Korea again May 8, 2012
ZIP typed attachment is disguising as an image file, and it actually contains executable file.
User will be infected by malicious files after extracting and executing ZIP file.
After being infected, clone file of malicious file will be created on "All Users" path.
And it adds registry on following path and makes run on booting.
svchost.exe tries to access TCP/IP, yet it doesn't connect certain host.
Spreading malicious file with social engineering is one of traditional technique. To use PC safely from security threats of these malicious attachments, we recommend you download latest security updates and obey following "Security management tips" for general users.
INCA Internet (Security Response Center / Emergency Response Team) runs responding system against various security threats.